ZeroHour

Vulnerabilities

3,513 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18232
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public A

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-16593
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticat

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.

NVD description · AI analysis pending
6.8
  • WordPress
CVE-2026-16592
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as l

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.

NVD description · AI analysis pending
2.7
  • WordPress
CVE-2026-15758
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-85657
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on a link.

NVD description · AI analysis pending
5.4
  • WordPress
CVE-2026-85575
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable t

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
6.4
  • WordPress, E-commerce
CVE-2026-89023
Missing Authorization in ThemeAtelier Domain For Sale WordPress Plugin REST API

The ThemeAtelier Domain For Sale plugin for WordPress before version 3.5.2 contains a missing authorization flaw (CWE-862) in its REST API endpoints, allowing unauthenticated attackers to reach protected resources without any credentials. The bug is triggered simply by sending crafted requests to the plugin's REST routes, which fail to verify user permissions. An attacker can retrieve stored offer records, delete arbitrary offers by numeric identifier, and pull dashboard statistics, exposing bidder contact information, offer details, private messages, verification tokens, and business data. Sites running any version prior to 3.5.2 with the plugin active are affected. No public proof-of-concept is known and the flaw does not appear in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

Do: Update Domain For Sale to version 3.5.2 or later immediately. Until patched, block unauthenticated access to the plugin's REST API namespace at the WAF or reverse proxy, and verify that REST permission callbacks are enforced. Afterward, audit offer records for unauthorized deletions or tampering, rotate any exposed verification tokens, and notify affected bidders if contact details or messages were disclosed.

8.8
  • ThemeAtelier Domain For Sale (WordPress plugin) before 3.5.2
nichelikely low thousands of sites at most (order of magnitude: ~1,000s)
CVE-2026-82519
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.

NVD description · AI analysis pending
2.3
  • WordPress
CVE-2026-87087
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

NVD description · AI analysis pending
  • WordPress
CVE-2026-89050
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

NVD description · AI analysis pending
4.3
  • WordPress
CVE-2026-88802
Unauthenticated Post Deletion in MDJM Event Management & Mobile Events Manager Plugins

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager plugin through 1.4.8.3 fail to check a capability, a nonce, or the type of record when processing a playlist-entry removal request, so the code permanently deletes whatever post ID the request identifies. Any unauthenticated attacker who can reach the affected site can send a crafted request to destroy arbitrary posts, pages, and media attachments, bypassing the WordPress trash so the content is unrecoverable without backups. The result is high-impact integrity loss (CVSS 3.1: 7.5, network vector, no privileges or user interaction required) but no confidentiality impact. Sites running these niche event/DJ-management plugins are affected. No public proof of concept or in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update MDJM Event Management to version 1.7.8.5 or later and Mobile Events Manager to a version newer than 1.4.8.3, or deactivate the plugin entirely if no fixed release is available for your version line. If patching must be delayed, use a WAF or firewall rule to block unauthenticated requests to the plugin's playlist-entry-removal AJAX/action endpoint. Because deletion bypasses the trash, verify working backups and audit the site for unexplained missing posts, pages, or media attachments.

7.5
  • MDJM Event Management (WordPress plugin) before 1.7.8.5
  • Mobile Events Manager (WordPress plugin) through 1.4.8.3 (<= 1.4.8.3)
nichelikely on the order of a few thousand sites or fewer (low thousands at most)
CVE-2026-88793
Unauthenticated Stored XSS in YouTube Embed WordPress Plugin 10.0–10.3

The YouTube Embed WordPress plugin versions 10.0 to 10.3 performs no authorisation check on one of its AJAX actions, with its only safeguard being a nonce that is printed on every front-end page, so any unauthenticated visitor can retrieve the nonce and invoke the action. Because the plugin also fails to escape stored data before rendering it, an attacker can persist arbitrary web scripts that execute in the browser of any user viewing the affected content, including administrators, enabling session hijacking and full site takeover. Any WordPress site running the plugin in the 10.0–10.3 range is affected. There is no known public PoC and the flaw is not listed in CISA's KEV, so exploitation is currently none known.

Do: Update to version 10.4 or later (or the latest release) immediately. Inspect the plugin's stored options and rendered embed content for injected scripts and log out/rotate admin sessions if tampering is found. If updating is not possible, deactivate and remove the plugin and review server logs for unauthenticated AJAX requests to the affected action.

8.8
  • YouTube Embed plugin (WordPress) YouTube Embed 10.0 to 10.3
moderate≈3,000–5,000 sites (plugin reports a few thousand active installs on WordPress.org)
CVE-2026-85129
Unauthenticated Stored XSS and Settings Wipe in Hoo Companion WordPress Plugin 1.0.2

The Hoo Companion WordPress plugin, version 1.0.2, performs no authorisation, validation, or sanitisation on one of its import features, which writes submitted data directly into the active theme's settings. An unauthenticated attacker can send a crafted request to this endpoint to inject arbitrary JavaScript that executes in the browsers of any site visitor, including administrators, enabling session hijacking and full site takeover. The same malicious request overwrites and destroys the site's existing theme settings, breaking the site's appearance and configuration. Any WordPress site running the plugin alongside its companion theme is affected. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time.

Do: Remove or deactivate the Hoo Companion plugin until a patched version newer than 1.0.2 is available, and check the plugin's repository for security advisories. Inspect the active theme's settings for unexpected or foreign scripts and restore them from a known-good backup, since exploitation wipes legitimate settings. Review administrator accounts and sessions for compromise, and use a WAF rule to block unauthenticated requests to the plugin's import endpoint if it must remain enabled.

8.8
  • Hoo Companion (WordPress plugin vendor) Hoo Companion WordPress plugin 1.0.2 and prior
CVE-2026-81648
Unauthenticated Arbitrary File Deletion in CryptoPayment Gateway WordPress Plugin

The CryptoPayment Gateway WordPress plugin versions 1.2.1 and 1.2.2 fails to enforce an authorization (capability) check on one of its AJAX endpoints, which means any unauthenticated visitor can invoke what should be administrative-only operations. An attacker triggers the flaw simply by sending a crafted request to the unprotected AJAX action — no valid session, nonce, or credentials are required. Successful abuse lets the attacker delete arbitrary files on the server (potentially destroying the site or enabling a WordPress reinstallation takeover by wiping wp-config.php), overwrite the payment gateway configuration, and retrieve stored wallet credentials in cleartext, which could lead to direct theft of cryptocurrency funds. Sites running the plugin at versions 1.2.1–1.2.2 are affected regardless of configuration. There is no known public PoC and no evidence of in-the-wild exploitation to date, though the CVSS 10.0 rating and trivial preconditions make patching urgent.

Do: Update the CryptoPayment Gateway plugin immediately to the latest version (anything after 1.2.2, per the advisory's fixed-range). Treat all wallet credentials and API keys handled by the plugin as compromised: rotate wallets/seed phrases, review the gateway configuration for unauthorized changes, and verify site files for unexpected deletions or modifications (including restoring from backup if wp-config.php was targeted). Until patched, block unauthenticated AJAX requests to the plugin's endpoints via WAF rules or disable the plugin.

10.0
  • CryptoPayment Gateway (WordPress plugin) 1.2.1 – 1.2.2
nicheunknown
CVE-2026-74933
Unauthenticated Config Overwrite and Stored XSS in GenieWords WordPress Plugin

The GenieWords WordPress plugin, versions 1.5.27 through 1.5.34, lacks authorization (capability and nonce) checks on several of its REST API and AJAX actions, which allows unauthenticated attackers to invoke those endpoints and overwrite the plugin's configuration. Because the plugin also decodes stored values before printing them, an attacker can inject arbitrary web scripts through the writable settings, resulting in persistent JavaScript that executes on every front-end page of the site. Successful exploitation (which requires a victim to load an affected page, per the UI:R in the CVSS vector) can lead to session theft, administrative action hijacking, and site-wide content manipulation, reflected in the high 8.8 CVSS score. Any site running GenieWords 1.5.27–1.5.34 with the plugin active is affected. No public proof-of-concept is known and the flaw is not on the CISA KEV list, so no active exploitation has been confirmed.

Do: Update GenieWords to a version newer than 1.5.34 as soon as a patched release is available; if none exists yet, deactivate and remove the plugin. Until remediated, block or restrict unauthenticated access to the plugin's REST API (e.g., /wp-/geniewords/) and admin-ajax.php actions via a WAF rule. Review the plugin's stored configuration for unexpected changes or injected script payloads, and check site pages and logs for signs of malicious JavaScript or unauthorized settings modifications.

8.8
  • GenieWords (WordPress plugin) 1.5.27 – 1.5.34
CVE-2026-89080
Unauthenticated 2FA Reset Bypass in Really Simple Security WordPress Plugin

The Really Simple Security WordPress plugin before version 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor authentication enrolment, undermining the plugin's own second factor. An attacker who already knows a victim's password can trigger this reset, bypass email 2FA, and log in to obtain that user's session — up to administrator, enabling full site takeover. Any WordPress site running a version below 9.8.1, particularly those relying on the plugin's email-based two-factor authentication, is affected. The flaw carries a high CVSS 3.1 score of 7.5 and is classified as an authentication vulnerability (CWE-287). No public proof of concept exists, the issue is not on CISA's Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

Do: Upgrade Really Simple Security to version 9.8.1 or later immediately. Check user accounts for unexpected 2FA enrolment resets and review login/session logs for the vulnerable period, rotating credentials and invalidating sessions for administrator accounts if anything looks off. Because the attack requires prior knowledge of the password, enforce strong unique passwords and consider app-based (TOTP) second factors where available.

7.5
  • Really Simple Plugins Really Simple Security (WordPress plugin) before 9.8.1
mass≈4,000,000+ WordPress sites (plugin reports 4M+ active installs), of which only sites with email 2FA enabled are practically exploitable
CVE-2026-88995
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allow

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-88912
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and i

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

NVD description · AI analysis pending
4.2
  • WordPress
CVE-2026-88764
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level conf

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.

NVD description · AI analysis pending
5.4
  • WordPress
CVE-2026-86407
The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account n

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.

NVD description · AI analysis pending
3.7
  • WordPress
CVE-2026-86406
Payment Bypass Privilege Escalation in User Registration & Membership Plugin < 5.2.8

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase and does not validate the payment method or the plan submitted with it, so any authenticated user — even a low-privileged subscriber — can claim a paid membership plan without paying. When a site owner has mapped a paid plan to a privileged WordPress role, this becomes privilege escalation, potentially granting full administrator access. The flaw (CWE-269, CVSS 3.1: 7.5 high) is triggered simply by submitting a crafted membership purchase request while logged in as any registered user. Affected sites are WordPress installations running the plugin below 5.2.8, particularly those that map purchasable plans to privileged roles. No public PoC is known, the CVE is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

Do: Update to User Registration & Membership 5.2.8 or later immediately. Review your membership-plan-to-role mappings and remove any that assign privileged roles (especially administrator) to purchasable plans. Audit users, role assignments, and payment records for accounts that received paid plans or role changes without a corresponding successful payment.

7.5
  • User Registration & Membership (WordPress plugin) < 5.2.8
CVE-2026-80072
The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthe

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.

NVD description · AI analysis pending
4.7
  • WordPress
CVE-2026-80071
Author-to-Admin Privilege Escalation in User Registration & Membership Plugin < 5.2.8

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan, nor does it validate the plan a user attaches to their own account — a privilege-management flaw (CWE-269). An authenticated attacker with Author-level access or above can create or attach a membership plan that grants an arbitrary role, escalating their own account to Administrator. Successful exploitation effectively yields full site takeover, since an administrator can install plugins, modify all content, and access all site data. All sites running a version before 5.2.8 are affected, with multi-user sites where non-administrators hold authoring roles at greatest risk. No public proof of concept exists, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

Do: Update to User Registration & Membership 5.2.8 or later as soon as possible. Audit your user list for unexplained Administrator accounts or role changes, and review any membership plans created or edited by non-administrator users. Until patched, restrict plan-authoring and publishing capabilities to trusted users and monitor audit logs for suspicious role assignments.

7.2
  • WPEverest User Registration & Membership (WordPress plugin) All versions before 5.2.8
moderateOn the order of tens of thousands of sites (≈10,000–100,000)
CVE-2026-77773
The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its publ

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-15451
Authenticated Privilege Escalation in MemberPress Corporate Accounts WordPress Plugin

The MemberPress Corporate Accounts plugin for WordPress contains a mass assignment flaw in its 'add_sub_account_user' function, which passes the raw 'userdata' array to 'wp_insert_user' without stripping dangerous keys such as 'role' or 'ID'. An authenticated attacker with subscriber-level access who holds a corporate account can exploit this over the network to create new administrator accounts or hijack existing administrator accounts by overwriting their email addresses. Successful exploitation grants full site takeover, since the CVSS vector scores high impact to confidentiality, integrity, and availability. Any WordPress site running the plugin at version 1.5.39 or earlier is affected, though 1.5.39 only partially patched the issue. No public proof-of-concept or in-the-wild exploitation is currently known, and the flaw is not listed in CISA's KEV catalog.

Do: Update the Corporate Accounts plugin to the latest available release, verifying with MemberPress that the version you install fully remediates the flaw beyond the partial fix in 1.5.39. Audit the site for unexpected administrator accounts and recently changed admin email addresses, and review corporate account holders for suspicious activity. Until fully patched, consider temporarily deactivating the Corporate Accounts add-on or restricting corporate account creation.

8.8
  • MemberPress Corporate Accounts plugin for WordPress all versions up to and including 1.5.39 (1.5.39 contains only a partial patch)
largelikely tens of thousands of sites (premium MemberPress add-on; MemberPress claims 600,000+ total installs, with Corporate Accounts among its widely deployed…
CVE-2026-10148
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.

NVD description · AI analysis pending
6.4
  • WordPress
CVE-2026-85200
Unauthenticated Local File Inclusion in GEO my WP WordPress plugin

The GEO my WP geolocation/mapping plugin for WordPress is vulnerable to an unauthenticated local file inclusion (CWE-98) in the gmw_posts_locator_ajax_info_window_loader function, affecting all versions up to and including 4.5.5.3. An unauthenticated attacker can send a crafted request to this function that causes the server to include and execute arbitrary .php files present on the host. This can be used to bypass access controls or obtain sensitive data, and becomes full remote code execution if the attacker can upload .php files that are then included, or in environments where PEAR is installed with register_argc_argv enabled. Any WordPress site running the plugin at version 4.5.5.3 or older is affected. As of now the flaw is not listed in CISA KEV and no public proof-of-concept is known.

Do: Update GEO my WP to the latest release available, i.e., any version newer than 4.5.5.3, as soon as possible. Until patched, use a WAF/firewall rule to block unauthenticated requests to the affected AJAX action and prevent upload of .php files to the server, and check server configurations (PEAR present with register_argc_argv enabled) where the flaw can escalate to full remote code execution. Review logs for anomalous calls to the info-window loader and for unexpected PHP file uploads.

7.5
  • GEO my WP WordPress plugin all versions up to and including 4.5.5.3
largetens of thousands of sites (plugin has roughly 30,000 active installs on WordPress.org)
CVE-2026-85198
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all version

The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-78175
PHP Object Injection to RCE in Tutor LMS WordPress Plugin (≤ 4.0.7)

Tutor LMS, a WordPress eLearning plugin, suffers from a PHP object injection flaw (CWE-502) in the `tutor_save_withdraw_account` AJAX handler, which accepts attacker-controlled `withdraw_method_field` values with no capability check beyond a nonce and stores them via `update_user_meta()` in a way that corrupts serialized string lengths. An authenticated user with subscriber-level privileges (or an unauthenticated attacker, if open user registration is enabled) who holds a valid nonce can therefore make `unserialize()` over-read into attacker-controlled bytes and inject an arbitrary serialized object. By chaining the plugin's bundled PayPal Composer autoloader with the `GuzzleHttp\Cookie\FileCookieJar` gadget, the attacker achieves remote code execution, writing attacker-controlled content to an attacker-specified filename on the server. All sites running Tutor LMS up to and including version 4.0.7 with the monetization feature enabled are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

Do: Update Tutor LMS to a release newer than 4.0.7 as soon as a patched version is published (no fixed version number is confirmed in the available data). As interim mitigation, disable the plugin's monetization/withdraw feature, restrict or close open user registration, and review `update_user_meta()`-stored withdraw account data for tampered serialized values. Sites that enabled monetization and registration should also audit for unexpected files written by web-server users during the exposure window.

8.8
  • Themeum Tutor LMS – eLearning and online course solution plugin for WordPress All versions up to and including 4.0.7
large≈100,000+ WordPress installs of Tutor LMS (plugin-directory active-install level), of which a smaller subset
CVE-2026-78006
+1 in the same advisory: …78159
Unauthenticated RCE in The Events Calendar WordPress Plugin

The Events Calendar WordPress plugin is vulnerable to unauthenticated remote code execution (CWE-502, unsafe deserialization) in all versions up to and including 6.17.4 via the is_safe_widget_instance function, whose protection can be bypassed because PHP fires magic methods during pre-parse while enable_rendering_widget_copied() forges a valid wp_hash integrity attribute before unserialize() is reached. The flaw is reachable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that lets an unauthenticated commenter immediately view their own still-pending comment, delivering attacker-injected block markup to the vulnerable code path before moderation occurs. Successful exploitation gives an unauthenticated attacker arbitrary code execution on the web server with full confidentiality, integrity, and availability impact. Any site running a vulnerable version is affected, but only when comments are enabled and visible on events. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.

Do: Update The Events Calendar to the latest available release (any version newer than 6.17.4) as soon as possible. Until patched, disable comments on events or prevent them from being publicly visible, since exploitation requires comments to be enabled and viewable on event pages. Review logs for pending comments submitted to events and unexpected widget/serialized data, and treat comment moderation queues on event posts with suspicion.

9.8<1% PoC ×2
  • StellarWP (The Events Calendar) The Events Calendar WordPress plugin All versions up to and including 6.17.4
mass≈200,000+ sites (plugin reports 200,000+ active installs on WordPress.org), with the exploitable subset smaller because comments must be enabled and visible on…
CVE-2026-77161
The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and includin

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the plugin's sync feature to be enabled (options['enabled']) and get_option('egoi_mapping') to be truthy, both of which reflect ordinary configured states for the plugin's core contact mapping functionality.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-17585
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-16482
Unauthenticated Blind SQL Injection in rtMedia WordPress Plugin

The rtMedia for WordPress, BuddyPress and bbPress plugin is vulnerable to time-based blind SQL injection through the 'compare' parameter in all versions up to and including 4.7.11, caused by insufficient escaping and lack of prepared statements. Any unauthenticated attacker can trigger it by sending a crafted request to a public page that embeds an rtMedia shortcode (such as [rtmedia_gallery]) with the rtmedia_shortcode GET parameter set, since RTMediaQuery::query() merges $_REQUEST into the query while validating only top-level keys. Successful exploitation lets the attacker append additional SQL queries and extract sensitive information from the site's WordPress database, including potentially user credentials. Any WordPress site running the plugin with a rtMedia shortcode on a publicly reachable page is affected. As of now there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.

Do: Update the rtMedia plugin to the newest release (any version newer than 4.7.11). Until patched, remove rtMedia shortcodes from public pages or use a WAF rule to block requests where the rtmedia_shortcode GET parameter is present along with nested 'compare' values. Review web server and WAF logs for requests containing the rtmedia_shortcode parameter, and check the database for signs of unexpected queries or data exfiltration.

7.5
  • rtCamp (rtMedia) rtMedia for WordPress, BuddyPress and bbPress (WordPress plugin) All versions up to and including 4.7.11
large≈100,000+ sites (plugin reports roughly 100k active installs on WordPress.org; the exploitable subset are sites with rtMedia shortcodes on public pages)
CVE-2026-11355
The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions up to, and including, 1.1. These handlers are registered on the wp_ajax_nopriv_* hook and contain no capability check, no nonce verification, and pass user-supplied data directly to update_option(). This makes it possible for unauthenticated attackers to overwrite arbitrary plugin option values stored in the wp_options table, including Point-of-Contact email configuration and skin/branding settings, which can be used to alter the appearance and behavior of the LMS for all site visitors.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87919
The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the u

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.

NVD description · AI analysis pending
4.9
  • WordPress, E-commerce
CVE-2026-87918
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI provid

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87916
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthentica

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87894
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87892
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing whe

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87891
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unau

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-87888
Subscriber-level stored XSS via missing authorization in YayPricing plugin (< 3.5.7)

The YayPricing WordPress plugin before version 3.5.7 fails to enforce an authorization check on a REST route that saves pricing rules, so any authenticated user with the subscriber role or above can write content into those rules. An attacker can embed JavaScript in a saved pricing rule, which then executes in the browser of an administrator who opens the plugin's settings page, making this a stored (persistent) cross-site scripting flaw. Because the script runs in the administrator's session, successful exploitation allows a low-privileged attacker to hijack admin access and fully compromise the site (for example, installing plugins or creating new administrators), consistent with the CVSS 3.1 score of 8.0 (high). Affected sites are those running YayPricing before 3.5.7, particularly WooCommerce stores with open user registration or other untrusted low-privileged accounts. No public proof of concept is known and the flaw is not on CISA's KEV list, so there is currently no evidence of exploitation in the wild.

Do: Update YayPricing to version 3.5.7 or later, which adds the missing authorization check on the affected REST route. Until patched, disable open user registration and audit existing subscriber-and-above accounts, since any authenticated user can inject the payload. Review saved pricing rules for unexpected JavaScript or unfamiliar entries (these execute when an admin opens the settings page) and check for signs of admin session hijacking or newly created administrator accounts.

8.0
  • YayCommerce YayPricing (WordPress plugin) all versions before 3.5.7 (< 3.5.7)
moderatelikely on the order of a few thousand sites (≈1,000–10,000), clearly an estimate
CVE-2026-87842
Unauthenticated Token Disclosure in Zonify WordPress Plugin Before 1.0.5

The Zonify WordPress plugin before version 1.0.5 fails to perform any capability or authentication check on the functionality that returns the site's stored account login token. An unauthenticated remote attacker can send a request to the affected endpoint and directly receive the token the site uses to connect to the owner's linked service account. With that token, the attacker can authenticate to the linked service as the site owner, gaining access to that connected account (CVSS 3.1: 7.5, high confidentiality impact with no privileges or user interaction required). Any WordPress site running Zonify prior to 1.0.5 is affected. The flaw is not in CISA's KEV catalog and there is no known public proof of concept or observed exploitation to date.

Do: Upgrade Zonify to version 1.0.5 or later immediately. Because the stored token could already have been harvested, re-authorize the plugin to revoke and replace the linked service token, and review the linked account for unauthorized sessions or activity. If the plugin is no longer needed, remove it entirely, and check access logs for unauthenticated requests hitting the plugin's endpoints.

7.5
  • Zonify (WordPress plugin) before 1.0.5
CVE-2026-87797
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through on

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.

NVD description · AI analysis pending
4.3
  • WordPress
CVE-2026-87759
Authenticated privilege escalation in Add User Autocomplete WordPress plugin (<1.2)

The Add User Autocomplete plugin for WordPress, in versions before 1.2, creates pending site-membership invitations without performing any capability check or CSRF nonce verification, and it honors a caller-supplied role for that invitation. As a result, any authenticated user — even one holding only the low-privileged Subscriber role — can send a crafted request to the invitation action, granting an account of their choosing (typically their own) the administrator role. Successful exploitation yields full administrative control of the affected site on a WordPress multisite network, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8, CWE-269 improper privilege management). Only multisite installations running the plugin below version 1.2 are exposed, and the attack is easiest where open registration lets attackers obtain a Subscriber account. No public proof-of-concept exists, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

Do: Upgrade to Add User Autocomplete 1.2 or later, which adds the missing capability and nonce checks. If updating is not immediately possible, deactivate the plugin on multisite networks, and audit pending site-membership invitations and user role lists for unexplained administrator accounts. Restricting open registration or minimizing low-privileged Subscriber accounts shrinks the pool of attackers who can trigger the flaw.

8.8
  • Add User Autocomplete plugin (WordPress) Add User Autocomplete before 1.2
nichelikely on the order of a few thousand sites at most, and only the multisite subset of those installs is exploitable
CVE-2026-86790
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, wh

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

NVD description · AI analysis pending
6.8
  • WordPress
CVE-2026-85681
Unauthenticated Arbitrary Option Overwrite in WP Component WordPress Plugin <= 2.2.4

The WP Component WordPress plugin through version 2.2.4 exposes an action to unauthenticated users that has no capability or nonce checks, and it takes both the option name and the option value directly from the request. This allows any unauthenticated attacker to overwrite arbitrary WordPress site options by sending a single crafted HTTP request. On single-site installations this leads to a full takeover, since the attacker can enable user registration with a default role of administrator and then create an administrator account. Any site running the plugin at or including version 2.2.4 is affected, and the advisory does not specify a fixed version. There is no known public proof of concept, no evidence of in-the-wild exploitation, and the CVE is not on CISA's KEV list.

Do: Upgrade WP Component to a version later than 2.2.4 as soon as a patched release is available, or remove the plugin entirely if no fix is forthcoming. Inspect the site's options for tampering — particularly 'users_can_register' enabled and 'default_role' set to administrator — and audit the users list for unauthorized administrator accounts. Review access logs for unauthenticated POST requests hitting the plugin's option-writing action endpoint.

9.8
  • WP Component (WordPress plugin) <= 2.2.4
CVE-2026-84171
Unauthenticated Arbitrary File Upload RCE in piclect WordPress Plugin ≤1.0

The piclect WordPress plugin through version 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory. An unauthenticated attacker can simply send a crafted file (for example, a PHP webshell) to the plugin's upload endpoint and then reach it via its public URL, achieving arbitrary code execution and full server compromise. Any site running piclect through 1.0 with the plugin active is affected, and the flaw requires no authentication, user interaction, or privileges (CVSS 9.8). There is no known public PoC and the issue is not in the CISA KEV catalog, so exploitation status is currently none known, though the attack itself is trivial to reproduce. Defenders should treat any site running this plugin as potentially compromised.

Do: There is no indicated patched version, so remove or disable the piclect plugin entirely until a fixed release is available. Immediately inspect the plugin's public upload directory and the webserver for unexpected files (especially .php or .phtml shells) and rotate credentials/keys if any are found. As an interim control, block unauthenticated POST requests to the plugin's upload endpoint at the WAF or reverse proxy.

9.8
  • piclect (WordPress plugin) piclect through 1.0 (<= 1.0)
unknown; plausibly only a small number of sites running an obscure plugin
CVE-2026-84099
Unauthenticated PHP Object Injection in wpstorecart WordPress Plugin ≤5.0.7

The wpstorecart WordPress plugin, through version 5.0.7, does not prevent direct, unauthenticated access to a bundled add-on that deserializes attacker-supplied input without restricting the permitted PHP classes. A remote, unauthenticated attacker can send a crafted serialized payload to this add-on and inject arbitrary PHP objects into the application. The injected objects can be escalated — potentially to remote code execution, data theft, or site takeover — when a suitable gadget chain (e.g., from another installed plugin or theme) is present on the site, which is why the CVSS attack complexity is rated high. Any WordPress site running wpstorecart 5.0.7 or earlier is affected, with no privileges or user interaction required to trigger the flaw. No public proof of concept is known, the CVE is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

Do: Because the advisory identifies no fixed version, the safest action is to deactivate and remove wpstorecart (5.0.7 or earlier) from any site still running it and migrate to a actively maintained e-commerce plugin. If removal must be delayed, block direct, unauthenticated HTTP requests to the bundled add-on via a WAF or server-level rule. Operators should also audit affected sites for signs of compromise such as unexpected administrator accounts, modified plugin or theme files, and unknown scheduled tasks.

8.1
  • wpstorecart (WordPress plugin) through 5.0.7 (all versions <= 5.0.7)
nichelikely hundreds to low thousands of sites at most (no official active-install count available)
CVE-2026-84047
Unauthenticated SQL Injection in Album Cover Finder WordPress Plugin ≤0.7.0

The Album Cover Finder WordPress plugin through version 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, creating an unauthenticated SQL injection flaw. A remote attacker triggers it by sending a crafted request to the plugin's affected endpoint — no account, privileges, or user interaction are required. Successful exploitation lets the attacker read sensitive data from the WordPress database (the CVSS 3.1 score of 8.6 reflects high confidentiality impact across a changed scope), while integrity and availability are not directly affected per the scoring. Any site running the plugin at or below version 0.7.0 is affected. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

Do: No patched version is identified in the data (0.7.0 appears to be the latest release), so the safest action is to deactivate and remove the plugin from any site where it is not essential. If it must remain, apply a WAF or virtual-patching rule that blocks SQL-injection patterns against the plugin's endpoints and review database and access logs for anomalous queries. Because injected queries can expose user tables and password hashes, consider rotating database credentials and forcing password resets for privileged accounts on affected sites.

8.6
  • WordPress (Album Cover Finder plugin) Album Cover Finder through 0.7.0 (all versions up to and including 0.7.0)
nichelikely on the order of a few hundred or fewer sites; exact count unknown